PT-2025-17726 · Apache+2 · Apache Httpclient+3
Joe Gallo
·
Published
2025-03-06
·
Updated
2025-08-07
·
CVE-2025-27820
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HttpClient versions 5.4.0 through 5.4.2
Description
A bug in PSL validation logic disables domain checks, affecting cookie management and host name verification. This issue was discovered by the Apache HttpClient team.
Recommendations
For Apache HttpClient versions 5.4.0 through 5.4.2, update to version 5.4.3 to resolve the issue. As a temporary workaround, consider restricting cookie management and host name verification until the update is applied.
Fix
LPE
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Httpclient
Bamboo
Confluence